#VU56813 Improper Authorization in Handler for Custom URL Scheme in macOS
Published: September 22, 2021
macOS
Apple Inc.
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation in in macOS Finder when processing custom URI schemes, such as File:// or fIle://. A remote attacker can create a specially crafted file with inetloc extension, send it as an email attachment, trick the victim to open the email and execute arbitrary OS commands on the system.